Description
Authentication bypass vulnerability in Apache Zeppelin allows an attacker to bypass Zeppelin authentication mechanism to act as another user. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.
Remediation
References
http://www.openwall.com/lists/oss-security/2021/09/02/2
https://lists.apache.org/thread.html/r768800925d6407a6a87ccae0ec98776b7bda50c0e3ed3d0130dad028%40%3Cannounce.apache.org%3E
https://lists.apache.org/thread.html/r768800925d6407a6a87ccae0ec98776b7bda50c0e3ed3d0130dad028%40%3Cusers.zeppelin.apache.org%3E
https://lists.apache.org/thread.html/r768800925d6407a6a87ccae0ec98776b7bda50c0e3ed3d0130dad028%40%3Cusers.zeppelin.apache.org%3E
https://lists.apache.org/thread.html/r99529e175a7c1c9a26bd41a02802c8af7aa97319fe561874627eb999%40%3Cusers.zeppelin.apache.org%3E
https://security.gentoo.org/glsa/202311-04
Related Vulnerabilities
CVE-2019-10333 Vulnerability in maven package org.jenkins-ci.plugins:electricflow
CVE-2020-7642 Vulnerability in npm package lazysizes
CVE-2021-22147 Vulnerability in maven package org.elasticsearch:elasticsearch
CVE-2010-2076 Vulnerability in maven package org.apache.axis2:axis2-kernel
CVE-2020-2114 Vulnerability in maven package org.jenkins-ci.plugins:s3